Repository navigation
fix: Added token validation on API to avoid security issues - #709
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved authentication, deployment-enforcement, error-handling, and Dependabot configuration issues remain.
Review effort: Lite
Findings: 1
Open (10)
Enforce authentication during the deployment process · New Apply cooldown to the intended uv update entries · New Merge API scopes instead of overwriting existing permissions · New Check az process exit code before reporting consent success · New Allow Azure CLI client tokens or use a supported identity · New Merge API scopes instead of overwriting existing permissions · New Allow Azure CLI client tokens or use a supported identity · New Fail when authentication is configured but token acquisition fails · New Fail when authentication is configured but token acquisition fails · New Renumber duplicate deployment guide sections · New
What changed in this PR
Adds API bearer-token support, Microsoft Entra authentication configuration, workflow action pinning, and Dependabot cooldown settings.
Changes:
- Added token-aware upload and deployment scripts.
- Added authentication setup scripts and documentation.
- Pinned GitHub Actions to commit SHAs.
- Added Dependabot cooldown configuration.
| File | Summary |
|---|---|
src/ContentProcessorAPI/samples/upload_files.sh |
Adds optional bearer-token uploads. |
src/ContentProcessorAPI/samples/upload_files.ps1 |
Adds optional bearer-token uploads. |
infra/scripts/post_deployment.sh |
Adds authenticated schema registration. |
infra/scripts/post_deployment.ps1 |
Adds authenticated schema registration. |
infra/scripts/configure_app_authentication.sh |
Configures Entra authentication. |
infra/scripts/configure_app_authentication.ps1 |
Configures Entra authentication. |
docs/DeploymentGuide.md |
Documents authentication deployment steps. |
docs/ConfigureAppAuthentication.md |
Documents authentication setup. |
.github/workflows/validate-bicep-params.yml |
Pins workflow actions. |
.github/workflows/test.yml |
Pins workflow actions. |
.github/workflows/test-automation.yml |
Pins workflow actions. |
.github/workflows/test-automation-v2.yml |
Pins workflow actions. |
.github/workflows/telemetry-template-check.yml |
Pins checkout action. |
.github/workflows/stale-bot.yml |
Pins stale action. |
.github/workflows/scheduled-Dependabot-PRs-Auto-Merge.yml |
Pins checkout action. |
.github/workflows/pylint.yml |
Pins workflow actions. |
.github/workflows/pr-title-checker.yml |
Pins PR validation action. |
.github/workflows/job-docker-build.yml |
Pins Docker and Azure actions. |
.github/workflows/job-deploy.yml |
Pins deployment actions. |
.github/workflows/job-deploy-windows.yml |
Pins Windows deployment actions. |
.github/workflows/job-deploy-linux.yml |
Pins Linux deployment actions. |
.github/workflows/job-cleanup-deployment.yml |
Pins Azure login action. |
.github/workflows/deploy.yml |
Pins deployment actions. |
.github/workflows/codeql.yml |
Pins CodeQL actions. |
.github/workflows/build-docker-image.yml |
Pins Docker build actions. |
.github/workflows/broken-links-checker.yml |
Pins link-checking actions. |
.github/workflows/azure-dev.yaml |
Pins Azure deployment actions. |
.github/workflows/azd-template-validation.yml |
Pins validation actions. |
.github/dependabot.yml |
Adds Dependabot cooldown configuration. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
fix: Fix authentication Script
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved critical and moderate issues affect configuration preservation, authenticated deployment retries, and Dependabot cooldown behavior.
Review effort: Lite
Findings: 5
Open (14)
Merge SPA redirect URIs instead of replacing them · New Merge SPA redirect URIs instead of replacing them · New Include authentication headers in the readiness probe · New Include authentication arguments in the readiness probe · New Enforce authentication during the deployment process Fail when authentication is configured but token acquisition fails Fail when authentication is configured but token acquisition fails Allow Azure CLI client tokens or use a supported identity Merge API scopes instead of overwriting existing permissions Allow Azure CLI client tokens or use a supported identity Check az process exit code before reporting consent success Merge API scopes instead of overwriting existing permissions Apply cooldown to the intended uv update entries Renumber duplicate deployment guide sections
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical authentication, authorization, and script execution issues remain unresolved.
Review effort: Lite
Findings: 6
Open (8)
Documented schema registration script lacks authentication · New Easy Auth rejects Azure CLI tokens due to allowed client restriction · New Allowed applications overwrite existing clients · New Bash script uses CRLF line endings · New PowerShell setup overwrites existing allowed applications · New Enforce authentication during the deployment process Deployment guide contradicts schema registration hook behavior · New PR description does not match the actual changes · New
Resolved since last review (13)
Include authentication arguments in the readiness probe Include authentication headers in the readiness probe Merge SPA redirect URIs instead of replacing them Merge SPA redirect URIs instead of replacing them Fail when authentication is configured but token acquisition fails Fail when authentication is configured but token acquisition fails Allow Azure CLI client tokens or use a supported identity Merge API scopes instead of overwriting existing permissions Allow Azure CLI client tokens or use a supported identity Check az process exit code before reporting consent success Merge API scopes instead of overwriting existing permissions Apply cooldown to the intended uv update entries Renumber duplicate deployment guide sections
The committed blob used CRLF, causing 'bash infra/scripts/configure_app_authentication.sh' to fail on Linux/macOS/WSL/CI with \$'\r': command not found before any Azure command runs. Convert to LF so the documented invocation works cross-platform. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved moderate findings affect authentication configuration, portability, readiness checks, and schema registration.
Review effort: Lite
Findings: 1
Open (8)
Enforce authentication during the deployment process Bash script requires undocumented jq prerequisite · New PowerShell issuer omits the documented /v2.0 suffix · New Bash UUID fallback fails without python on macOS · New Generated issuer omits the required /v2.0 suffix · New Startup probe does not verify backend readiness · New Startup probe does not verify backend readiness · New PR description does not match the submitted authentication changes · New
Resolved since last review (7)
PowerShell setup overwrites existing allowed applications Bash script uses CRLF line endings Allowed applications overwrite existing clients Easy Auth rejects Azure CLI tokens due to allowed client restriction Documented schema registration script lacks authentication PR description does not match the actual changes Deployment guide contradicts schema registration hook behavior



Purpose
Workflow Security and Reliability Improvements:
uses:statements in workflow files now reference actions by commit SHA instead of tags, includingactions/checkout,azure/login,docker/build-push-action,docker/setup-buildx-action,Azure/setup-azd,lycheeverse/lychee-action,github/codeql-action,microsoft/template-validation-action,amannn/action-semantic-pull-request,actions/setup-python, andactions/stale. This ensures deterministic builds and mitigates risks from upstream changes. [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20] [21] [22] [23] [24] [25] [26] [27] [28] [29] [30] [31]Dependabot Configuration:
cooldownsection with a default of 7 days to the.github/dependabot.ymlfile, controlling the frequency of grouped updates foruvdependencies.Does this introduce a breaking change?
Golden Path Validation
Deployment Validation
What to Check
Verify that the following are valid
Other Information